Vulnerability Description
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Activity Report CSV without formula escaping, allowing a low-privileged authenticated user to store a formula-like User-Agent that may execute when a report viewer opens the exported CSV in spreadsheet software. This issue is fixed in version 8.5.0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Snipeitapp | Snipe-It | < 8.5.0 |
Related Weaknesses (CWE)
References
- https://github.com/grokability/snipe-it/commit/7b7d2c87fbc965a7933b1bf9e3f2c331bPatch
- https://github.com/grokability/snipe-it/releases/tag/v8.5.0Release Notes
- https://github.com/grokability/snipe-it/security/advisories/GHSA-whrx-mmgr-gpcfPatchVendor Advisory
FAQ
What is CVE-2026-55452?
CVE-2026-55452 is a vulnerability with a CVSS score of 7.3 (HIGH). Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Acti...
How severe is CVE-2026-55452?
CVE-2026-55452 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-55452?
Check the references section above for vendor advisories and patch information. Affected products include: Snipeitapp Snipe-It.